- Location
- PZZ04 - DXC Manila IPC McKinley Hill (PZZ04), Philippines
- Type
- Full-time
- Experience
- 5+ years
- Source
- Workday
Description
Job Description:
DXC Technology is a Fortune 500 Global IT Services Leader. Our more than 130,000 people in 70-plus countries are entrusted by our customers to deliver what matters most. We use the power of technology to deliver mission critical IT services that transform global businesses. We deliver excellence for our customers, colleagues and communities around the world.
Accelerate your career and reimagine the possibilities with DXC!
We inspire and take care of our people. Work in a culture that encourages innovation and where brilliant people embrace change and seize opportunities to advance their careers and amplify customer success. Leverage technology skills and deep industry knowledge to help clients. Work on transformation programs that modernize operations and drive innovation across our customer’s entire IT estate using the latest technologies in cloud, applications, security, IT Outsourcing, business process outsourcing and modern workplace.
DXC Philippines is an award-winning Employer of Choice and a recipient of the Global Best Employer Brand and Linkedin’s Top 15 Companies in the Philippines.
Essential Job Functions
- Perform advanced SOC monitoring, triage, and investigation of complex security alerts and incidents across customer environments.
- Utilize Splunk Enterprise Security and SPL for security investigations, threat hunting, detection validation, correlation searches, and detection tuning.
- Execute structured incident response activities, including analysis, escalation, containment coordination, recovery validation, RCA, and post-incident reviews.
- Communicate security findings, risks, recommendations, and incident status to technical teams, customers, and business stakeholders.
- Prepare accurate, evidence-based incident reports, executive summaries, case documentation, and improvement recommendations.
- Identify detection gaps, false positives, alert noise, and recurring security patterns; recommend improvements to SOC processes and detection logic.
- Contribute to threat hunting, SOC playbooks, knowledge articles, and mentoring of junior analysts.
Basic Qualifications
- 5+ years of experience in cybersecurity/SOC operations, with Tier 2.5 or Tier 3-level capabilities.
- Strong hands-on experience with Splunk Enterprise Security.
- Strong Splunk SPL skills, including building, modifying, interpreting, and troubleshooting queries.
- Hands-on experience with cybersecurity incident response and investigation.
- Knowledge of NIST-aligned incident response practices.
- Experience investigating security events using endpoint, network, identity, cloud, email, application, and SIEM telemetry.
- Strong written and verbal communication skills, including customer-facing communication.
- Experience preparing technical incident reports, RCA/PIR documentation, and executive summaries.
Other Qualifications
- Experience with MITRE ATT&CK, threat intelligence, IOC/TTP analysis, threat hunting, SIEM rule tuning, and SOC playbooks.
- Knowledge of Splunk notable events, correlation searches, dashboards, risk-based alerting, security domains, data models, lookups, macros, field extraction, and CIM.
- Experience identifying detection gaps, alert noise, normalization issues, and data-quality problems.
- Ability to coordinate incident response with infrastructure, endpoint, identity, application, and service delivery teams.
- Experience mentoring junior SOC analysts and contributing to SOC process improvements.
- Preferred certifications include Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, GCIH, GCED, GCFA, CySA+, CISSP, SC-200, or SC-100.
Compensation and benefits are the heart of our employment as we venture in offering security and stability to our colleagues. Health Insurance (HMO) for you and dependents upon hiring
Life Insurance coverage from day 1 of employment
15 - 20 days vacation and 15 Days Sick Leave
Expanded maternity leave up to 120 days and Maternity Benefits
Expanded paternity leave up to 30 days
Non-Taxable Allowance (De-minimis)
Company-sponsored trainings upskilling, and certification
Flexible Working Arrangements
Healthy and Encouraging Work Environment
Recognition and Pay for Performance Culture
Supplemental Pay (Standby/Shift)
Covid19 Support
Retirement Program
Employee Assistance Program
If you are motivated to deliver excellent result, want to grow your career and make a difference come join us!
At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.
Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here.